CVE-2023-20198
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Softw...
Affects 5 products across 2 vendors.
A critical vulnerability in the web UI feature of Cisco IOS XE Software allows an unauthenticated attacker to gain initial access and create a local user account. The attacker can then escalate privileges to root and deploy an implant. This poses a significant risk to network infrastructure and could disrupt critical operations, especially in industrial settings where network devices manage communication between control systems and HMIs.
BSID: BS-2023-GLOBAL-257171-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2023-20198?
What is the CVSS score for CVE-2023-20198?
Is CVE-2023-20198 actively exploited?
How do I remediate CVE-2023-20198?
What systems are affected by CVE-2023-20198?
What NERC-CIP standard applies to CVE-2023-20198?
What IEC 62443 requirement maps to CVE-2023-20198?
| CVE ID | CVE-2023-20198 |
|---|---|
| BSID | BS-2023-GLOBAL-257171-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2023-10-16 |
| Last Modified | 2025-10-28 |
| ICS Relevance | 75% |
| Weakness (CWE) | |
| Verticals | |
| Domains | |
| Source | NVD |
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.
Source: NIST NVD / MITRE CVE Database
The vulnerability exists in the web UI feature of Cisco IOS XE Software. An unauthenticated attacker can exploit CVE-2023-20198 by sending a crafted HTTP request to the web interface, which allows them to gain initial access and create a local user account with normal user privileges. The attacker then leverages this account to exploit another vulnerability (CVE-2023-20273) to escalate privileges to root. With root access, the attacker can modify the file system, deploy implants, and potentially disrupt industrial processes by manipulating network configurations. The attacker must have network access to the web interface, typically reachable from the same network segment as the device.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Cisco | Ios Xe | — |
| Rockwell Automation | Allen-Bradley Stratix 5200 Firmware | — |
| Rockwell Automation | Allen-Bradley Stratix 5200 | — |
| Rockwell Automation | Allen-Bradley Stratix 5800 Firmware | — |
| Rockwell Automation | Allen-Bradley Stratix 5800 | — |
| CISA KEV | ● Active Exploitation Confirmed (added 2023-10-16) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict access controls on the web interface of affected Cisco devices. Restrict access to the web interface to trusted IP addresses using ACLs at the network perimeter (Purdue Level 2/3 boundary). Enable HTTPS and disable HTTP management. Consider deploying a web application firewall (WAF) to monitor and block suspicious activity.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
CIP-007-R1 requires the identification and disabling of unnecessary ports and services. The vulnerable web management interface represents an unnecessary service on BES Cyber Assets if remote management is not required.
IEC 62443 SR 3.5 (Input Validation) is directly violated. The firmware fails to validate input parameters before processing, enabling unauthorized access and privilege escalation.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-23 |
| SHA-512 Audit Hash | 2896e931043d985973440e7ad50303a0d43a3470d7a42d604bd452d6decf3c5e29a960da27a2c478cc1f77d64fcaa072545d0e295e632f2e0fc9cec9b4fae6df |
This Vulnerability Is Being Actively Exploited
CVE-2023-20198 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →